
Agent Envelope Mcp
io.github.BlackBoxEngineeringv1.0.1更新於 Sep 29, 2026
Neutral MCP server for AgentEnvelope authority: sovereign verify + vault verify/lookup/mint.
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Agent Envelope Mcp,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
agent-envelope-mcp
[agent-envelope-mcp MCP server]
agent-envelope-mcp is the MCP adapter for AgentEnvelope.
Any MCP-capable runtime can check delegated authority before it acts: OpenAI Agents SDK, OpenAI Responses remote MCP, Claude Desktop, Cursor, LangChain, LangGraph, CrewAI, or a custom runtime.
Prompts can request actions; AgentEnvelope decides whether the actor has authority to perform them.
Choose Your Mode
Local stdio:
Streamable HTTP:
The HTTP endpoint is:
Health check:
No API key is needed to start the server or to use sovereign signature/record
verification. Hosted-governance tools require AE_API_KEY or, in HTTP mode, an
Authorization: Bearer <portal-api-key> header.
For verification-only deployments, set AE_TOOLS=readonly. In that mode the
server does not register ae_mint, so MCP clients can only call sovereign
verification and hosted read/query tools.
Tools
Most tools return both readable MCP content and machine-readable
structuredContent.
Runtime Rule
Call AgentEnvelope before the real action. Execute only if allowed === true.
Do not pass AE_MINT_MATERIAL, vault roots, seeds, or private domain material to
the model or MCP client. Keep those in the bot runtime secret store.
Local MCP Config
OpenAI Agents SDK
OpenAI Responses Remote MCP
Use Streamable HTTP mode locally, or point OpenAI at your deployed MCP URL after the web/API edge is configured to serve the MCP HTTP endpoint:
For local HTTP testing, start the server:
Then use:
LangChain / LangGraph
Prompt Escalation Pattern
Example attack:
Expected runtime flow:
- The model proposes or attempts the action.
- The runtime calls
ae_authorize_action. - AgentEnvelope returns
allowed: false. - The runtime blocks execution.
- The hosted or local verification report records the denial.
Denied actions are useful outcomes: they show that authority boundaries held.
Programmatic Use
Environment
Security Notes
- Verification-only tools are annotated as read-only.
ae_mintis annotated as a governed, non-idempotent hosted action.- API keys meter service access; signatures prove authority.
- The runtime keeps secrets. The model asks for authority; AgentEnvelope returns the decision.
- Never expose mint material, vault roots, seeds, or private domain-scoped authority material to the model.
License
Apache-2.0 - see NOTICE for attribution.
來源:README.md,提交 f8799da
工具
0版本歷史
1- v1.0.1最新Sep 16, 2026


